Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15574

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information disclosure, potentially allowing an attacker to harvest credentials and sensitive conversation content.

Отчет

This Moderate flaw in the vllm-orchestrator-gateway component causes sensitive data, including bearer tokens and chat payloads, to be logged at a DEBUG level by default. In Red Hat OpenShift environments, these logs are directed to the node journal and cluster logging stack, making them accessible to any user with pods/log RBAC within the namespace. This persistent logging of credentials and private conversation content poses a significant risk of information disclosure.

Меры по смягчению последствий

To mitigate this issue, configure the RUST_LOG environment variable for the vllm-orchestrator-gateway component to a level higher than DEBUG, such as INFO. This will prevent the logging of sensitive authorization headers and full chat payloads to persistent logs. For example, set RUST_LOG=info in the deployment configuration. A restart of the affected pods or services is required for this change to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-vllm-orchestrator-gateway-rhel9Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-538
https://bugzilla.redhat.com/show_bug.cgi?id=2499594vllm-orchestrator-gateway: vllm-orchestrator-gateway: Authorization header and full chat payloads logged at hard-coded DEBUG default

EPSS

Процентиль: 17%
0.00259
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information disclosure, potentially allowing an attacker to harvest credentials and sensitive conversation content.

CVSS3: 7.5
github
около 1 месяца назад

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally identifiable information (PII) and secrets, to persistent logs. This sensitive data, including bearer tokens and chat content, can be accessed by any user with logging privileges. This vulnerability leads to information disclosure, potentially allowing an attacker to harvest credentials and sensitive conversation content.

EPSS

Процентиль: 17%
0.00259
Низкий

7.5 High

CVSS3